PCI DSS 9.4.2: All media with cardholder data is classified in accordance with the sensitivity of the data
PCI DSS v4.0.1 control 9.4.2: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.4.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4
All media with cardholder data is classified in accordance with the sensitivity of the data.
Summary
Classify media holding cardholder data by sensitivity, so people can tell what needs protecting.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.4.2.a | Examine documentation to verify that procedures are defined for classifying media with cardholder data in accordance with the sensitivity of the data. |
| 9.4.2.b | Examine media logs or other documentation to verify that all media is classified in accordance with the sensitivity of the data. |
The control that makes the rest of section 9.4 operable. Storage at 9.4.1, transport at 9.4.3 and 9.4.4, and destruction at 9.4.6 all depend on someone being able to tell that a given item is sensitive: an unlabelled box of reports gets treated as an unlabelled box of reports. The requirement does not prescribe a scheme, only that classification reflects sensitivity, so a simple two-level scheme applied consistently beats an elaborate one nobody uses. Worth pairing with 3.2.1: media you have no retention justification for should be destroyed rather than classified.
What to prepare
- The classification scheme, and what each level requires in handling.
- Evidence it is applied: labelling, or a storage convention that carries the same information.
- The link from classification to the handling controls in the rest of section 9.4.
How to implement it
1. Keep the scheme small. Two or three levels applied consistently is what people can follow; a five-level taxonomy is what gets ignored under time pressure.
2. Classify the container where labelling each item is impractical. A secure cabinet designated for card-bearing material carries the classification without anyone labelling every receipt.
3. Avoid labels that advertise value. A box marked "cardholder data" tells a thief exactly what to take; an internal code that staff know and outsiders do not achieves the same handling.
4. Tie it to the handling rules. Classification with no consequence is administrative work. Each level should say plainly how it is stored, moved and destroyed.
Where this commonly fails
- A scheme documented and never applied to the media actually held.
- Labels that make sensitive material easy for an outsider to identify.
- Electronic media classified while paper is not, or the reverse.
- Classification levels that no handling rule refers to.
Related controls
Others in section 9.4:
| Control | What it requires |
|---|---|
| 9.4.1 | All media with cardholder data is physically secured |
| 9.4.1.1 | Offline media backups with cardholder data are stored in a secure location |
| 9.4.1.2 | The security of the offline media backup location(s) with cardholder data is reviewed at least… |
| 9.4.3 | Media with cardholder data sent outside the facility is secured… |
| 9.4.4 | Management approves all media with cardholder data that is moved outside the facility… |
| 9.4.5 | Inventory logs of all electronic media with cardholder data are maintained |
| 9.4.5.1 | Inventories of electronic media with cardholder data are conducted at least once every 12 months |
| 9.4.6 | Hard-copy materials with cardholder data are destroyed when no longer needed for business… |
| 9.4.7 | Electronic media with cardholder data is destroyed when no longer needed for business or legal… |
← 9.4.1.2 · All controls · 9.4.3 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.